ADR 0191: the mesh's names are known by where they were composed, not by their suffix

A progressive insight: the rule and its check were stated as a suffix test; the mesh composes both
names of a route and publishes its internal one. The decision is unchanged.
This commit is contained in:
2026-10-03 15:39:07 +02:00
parent 27c6881287
commit ca8a865e73
2 changed files with 17 additions and 9 deletions
@@ -11,6 +11,15 @@ supersedes-in-part:
# 191. The mesh's resolver holds only the mesh's own names; a public name resolves publicly
> **Progressive insight — 2026-10-03.** The first implementation told the mesh's names from public
> ones by their spelling — a name ending in the mesh suffix — and this record said so: the Decision
> read *"only names under its own suffix"*, and the roster check *"every name the roster carries ends
> in the mesh suffix"*. The mesh needs no such test: it composes both names of every route itself,
> `name` from the node's public domain and `internal-name` from its own domain under the serving node
> (ADR 0151), and publishes the second. Which names are its own is known from where each was
> composed. Both sentences now say that; what was decided — a public name is never given a private
> answer — is unchanged.
## Context
**[ADR 0066](0066-public-routing-is-name-agnostic.md) published every routed name into internal
@@ -63,7 +72,8 @@ every public name the mesh serves, is forwarded and resolves publicly. Chosen.
## Decision
**The mesh publishes into internal resolution only names under its own suffix.** A machine's name,
**The mesh publishes into internal resolution only the names it composes for itself** — a
machine's name, and each route's `internal-name`, never a route's public `name`. A machine's name,
and through it every `<label>.<node>.internal`, resolve to that machine's private address. **A public
name is never given a private answer by the mesh**: it resolves through public DNS to the public
address, from members and non-members alike.
@@ -93,8 +103,8 @@ reachability — the lab — certifies its internal names and has no public name
**How each is checked:**
- **The roster:** the controller's catalogue tests assert that every name the roster carries ends in
the mesh suffix — a routed public name in it fails the build.
- **The roster:** the controller's catalogue tests assert that the names served are routes'
internal names and that no route's public name is among them — one published fails the build.
- **On a machine:** asking the machine's resolver for a public name the mesh serves returns the
public address, and asking it for that route's internal name returns the private one. Asked from a
non-member on a LAN the resolver answers, the first must hold as well.